From The Hacker News · 40 stories
Critical Flaw CVE-2026-46817 in Oracle E-Business Suite Exploited
A critical vulnerability in Oracle E-Business Suite, CVE-2026-46817, is now being actively exploited. Impacting versions 12.2.3 to 12.2.15, the flaw allows unauthenticated attackers to take control of Oracle Payments, necessitating immediate patching for affected instances.
Mustang Panda Exploits Zoho WorkDrive in Campaign Against Indian Government
The Mustang Panda group has launched campaigns targeting the Indian government, utilizing Zoho WorkDrive to transmit commands and steal data. This approach leverages legitimate service traffic to mask malicious activities and is part of broader espionage efforts aimed at India's hydropower initiatives and defense relations with Taiwan.
Microsoft Removes 119 Malicious Edge Extensions Involved in Malware Operation
Microsoft has removed 119 Edge extensions from its Add-ons store that concealed malware within images and fonts, compromising user credentials and facilitating ad fraud. The extensions, installed by up to 2.6 million users, utilized steganography to hide malicious code, operating undetected for years.
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A public proof-of-concept has been released for CVE-2026-55200, a critical flaw in libssh2 that may allow memory corruption and code execution for connected clients. This vulnerability affects all versions up to 1.11.1, posing significant risks as libssh2 is widely used in various applications and systems.
Hijacked npm and Go Packages Deploy Python Infostealer via VS Code Tasks
Cybersecurity researchers have identified hijacked npm and Go packages that deploy a Python-based infostealer on compromised systems. This method utilizes a concealed VS Code task to execute malware upon opening a project folder, facilitating data theft and persistent access.
Linux pedit COW Exploit Allows Root Access via Cached Binary Poisoning
A critical flaw in the Linux kernel's traffic-control subsystem allows unprivileged users to gain root access on vulnerable systems. The exploit targets the memory cache of setuid binaries, enabling attackers to inject and execute malicious code while bypassing file integrity checks.
CISA Warns of Exploited Flaws in Lantronix EDS5000 and PTC Windchill
The CISA has issued alerts concerning the exploitation of critical vulnerabilities in Lantronix EDS5000 and PTC Windchill systems. The Lantronix flaw allows code execution with escalated privileges, while the Windchill vulnerability enables remote code execution. Both alerts urge immediate patching to mitigate risks posed by these active threats.
Miasma Malware Compromises npm Packages and GitHub Actions
Researchers identified a supply chain attack involving Miasma malware targeting multiple npm packages and GitHub Actions. The attack compromises developer credentials to propagate malware across various software ecosystems, posing significant security risks.
Popular Chrome Ad Blocker Can Execute Arbitrary JavaScript Code
The Chrome ad blocker 'Adblock for YouTube,' with over 10 million installs, has been found to contain functionality for executing arbitrary JavaScript code remotely. This could potentially allow for significant privacy risks, including data theft, although no malicious activity has been reported to date.
New Mistic Backdoor Discovered Linked to KongTuke in Cyber Attack Campaigns
A new backdoor named Mistic has emerged in attacks directed at various sectors, linked to the KongTuke group. The stealthy malware is designed for long-term access, employing sophisticated evasion techniques such as memory-based execution and DLL side-loading, marking a significant threat to targeted organizations.
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited for Root Access
A zero-day vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20245, has been exploited to gain root access by an unknown threat actor. This flaw, identified by Mandiant, allows an authenticated attacker to execute commands by manipulating user input, raising serious security concerns for affected systems.
Law Enforcement Disrupts Amadey and StealC Malware Networks, Reclaims 27M Credentials
A law enforcement operation disrupted the Amadey and StealC malware networks, recovering 27 million stolen credentials and restricting over $47 million in criminal cryptocurrency assets. This takedown involved 326 servers and 142 domains and highlights the effectiveness of public and private sector collaboration in combating cybercrime.
Emergence of AI Threat Models Marks a New Era in Cybersecurity
The rise of frontier agentic AI models has drastically reduced the time from threat discovery to execution in cybersecurity. This shift poses a significant risk as AI can exploit vulnerabilities faster than human defenders can respond.
Compromised GitHub Actions Re-enabled, Resuming Mini Shai-Hulud Malware Execution
Two GitHub Actions repositories, previously compromised in May 2026 by the Mini Shai-Hulud campaign, were re-enabled on September 16, 2026, without the malicious code being removed. This allowed workflows referencing these actions to resume downloading and executing the malware, posing a software supply chain risk.
GitLab Email Address Vulnerability Allows Unauthorized Code Pushes and CI Job Execution
A vulnerability in GitLab's issue-by-email feature allows anyone with a user's private email address to push code and run CI/CD jobs as that user. This occurs because the email address acts as a credential, and GitLab does not verify the sender, enabling unauthorized actions on any project the user can access.
Placeholder domain "third-party.com" used in dev docs now hosts ClickFix attacks
The domain "third-party.com", commonly used as a placeholder in developer documentation, is now serving a fake Cloudflare verification page that attempts to trick Windows users into executing malicious PowerShell commands. This development is significant because it turns a widely accepted documentation practice into a security vulnerability, potentially exposing developers and users to malware through a trusted, yet compromised, resource.
Browser Extension Vulnerability Affects AI Assistants in Chrome, Edge, and Other Browsers
Security researchers at Forever Security demonstrated that a common browser extension could hijack AI assistants in five Chromium-based products, including Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude in Chrome extension. This vulnerability allows an attacker's extension to control the AI agent, and in some cases, access user files or activate the camera and microphone, by impersonating the AI vendor's trusted web page.
China-Aligned FamousSparrow Group Deploys New SparroWocky Backdoor in Latin America
The China-aligned threat actor FamousSparrow has been deploying a new C++ backdoor named SparroWocky in attacks targeting government agencies across Latin American countries since at least August 2025. This new modular backdoor, which replaces SparrowDoor as the group's primary implant, is capable of executing arbitrary files, acting as a TCP proxy, running commands, and collecting system information. Researchers theorize the campaign aims to monitor local government reactions to U.S. pressures in the region.
BIND 9 Updates Address 14 Vulnerabilities, Including Critical DoH Crash Flaw
The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 to fix fourteen security vulnerabilities in its open-source DNS server software. One critical flaw, CVE-2026-77692, allows an unauthenticated attacker to crash a BIND server configured for DNS-over-HTTPS (DoH) with a single crafted request. These updates are important for maintaining the stability and security of DNS infrastructure.
Microsoft Reports AI-Enhanced Invoice Scam Emails Targeting Businesses
Microsoft security researchers identified a new wave of business email compromise (BEC) invoice scams using AI to create more convincing and tailored fraudulent emails. Attackers are combining executive impersonation, vendor branding, and fabricated email chains to increase legitimacy, with a campaign in early August targeting over a million users, primarily in the US.
WeChat Zero-Click Worm Demonstrated via Incoming Calls, Patched by Tencent
Security researchers at Calif developed and demonstrated a zero-click worm that could take over WeChat accounts on iPhone and Android via incoming calls from existing contacts. Tencent has since patched the exploit for all users, blocking the attack vector. This vulnerability was significant because it allowed account compromise without user interaction, affecting a platform with 1.439 billion monthly active users.
Deceptive Android Apps Exploit Google Play Early Access Program to Evade Reviews
Threat actors are misusing Google Play's Early Access program to distribute deceptive Android applications. These apps, which promise rewards or premium content, bypass public reviews and ratings, primarily serving ads to users to generate revenue. Bitdefender identified this activity, noting that some apps, like a Grand Theft Auto imitator, accumulated over a million downloads before removal.
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Seizes $52.8 Million in Crypto
The U.S. Department of Justice (DoJ) and Treasury Department took coordinated actions against Xinbi Guarantee, an illicit online marketplace, seizing $52.8 million from 52 cryptocurrency wallets and sanctioning the platform. Xinbi Guarantee, created in 2022, facilitated cyber scams, money laundering, and human trafficking, processing at least $24 billion in transactions.
Plex urges users to update desktop clients and media servers for security patches
Plex has released updates for its Media Server and Desktop client to address multiple security vulnerabilities and is urging users to update immediately. These patches are critical as Plex has emailed affected users, a rare action, indicating the severity of the flaws.
12-Year-Old PostgreSQL Vulnerability Allows Database and Server Takeover
A cybersecurity firm discovered a critical vulnerability, CVE-2026-6471 (PostGREShell), in PostgreSQL versions released since 2014, enabling attackers with low privileges to achieve remote code execution and privilege escalation. This flaw, stemming from missing authorization in logical decoding, allows unauthorized file loading and execution, posing a significant risk to the tens of thousands of companies using PostgreSQL.
Thomson Reuters C-Track Platform Breach Exposes US and Canadian Court Data
Thomson Reuters disclosed a data breach affecting its C-Track court case management platform, exposing sealed court information and sensitive personal data from courts in at least 12 U.S. states, the U.S. Virgin Islands, and Canada. The breach, discovered on June 30, involved unauthorized access to files from March through June, potentially compromising names, Social Security numbers, and medical information, though no misuse has been reported.
GPUThor Rowhammer Attack Bypasses NVIDIA ECC on Ampere GPUs for Root Access
Researchers at the University of Toronto developed GPUThor, a new Rowhammer attack that bypasses NVIDIA's ECC protections on Ampere-class GPUs, enabling denial-of-service and root-level privilege escalation. This attack significantly increases bit-flip rates compared to previous methods, making exploitation practical within minutes.
AnonyMousKIT PhaaS uses AI voice agents to phish iPhone passcodes and disable Activation Lock
A new phishing-as-a-service (PhaaS) platform named AnonyMousKIT automates the retrieval of iPhone passcodes and disables Apple's Activation Lock feature. This service facilitates a criminal ecosystem for selling stolen iPhones, harvesting Apple IDs, and accessing iCloud backups and Keychain credentials.
ToxicPanda 2.0 Android Malware Expands Global Banking and Cryptocurrency Targeting
The Android banking malware ToxicPanda has been updated to version 2.0, significantly expanding its targeting scope to over 140 banking and cryptocurrency applications globally, up from 16. This new version includes 167 remote commands, improved credential harvesting, and new methods for privilege escalation and evading battery optimization policies, posing an increased threat to Android users.
Google Threat Intelligence Group Identifies Three Russian Cyber Espionage Clusters Abusing Authentication Flows
Google Threat Intelligence Group (GTIG) has identified three distinct suspected Russian cyber espionage clusters, UNC6293, UNC7005, and UNC5976, that are abusing legitimate authentication flows to target individuals in academia, aerospace, defense, government, and think tanks across Europe and the United States. These groups employ persistent phishing and social engineering tactics to compromise accounts, often by tricking users into setting app passwords or abusing OAuth flows. This matters because these techniques exploit trusted authentication processes, making them harder for targets to recognize as malicious and posing a significant threat to sensitive information.
Ransom Busters Affiliate Claims Hacking Ransomware Servers, Demands Payment from Victims
A ransomware affiliate named Ransom Busters is emailing victims, claiming to have hacked ransomware group servers and offering to delete stolen data for $20,000 to $60,000. This activity is unusual as it involves a third party proactively contacting victims with an offer to recover data and delete backups held by ransomware groups. The practice raises legal concerns under the U.S. Computer Fraud Abuse Act.
Microsoft Copilot revealed undocumented parameter allowing data exfiltration without user consent
Security researchers discovered a vulnerability in Microsoft 365 Copilot Enterprise that allowed data exfiltration without explicit user consent by querying Copilot itself. The AI assistant disclosed an undocumented prompt parameter, "?autorun=1", which, when combined with the "?q=" parameter, enabled silent execution of malicious prompts upon a user clicking a link. Microsoft has since mitigated this vulnerability.
New Android Malware WindRelay and SpyNote Steal Credit Card Data and Facilitate Loan Fraud
A new Android NFC relay malware, WindRelay, is being used with the SpyNote remote administration tool (RAT) to steal credit card data and take out loans in victims' names. This combination allows attackers to gain remote access to devices and relay live NFC transactions, enabling real-time financial fraud.
Hundreds of Fake Chrome VPN Extensions Route User Traffic Through Proxies
Security researchers identified 737 Chrome VPN extensions that routed user browser traffic through a single SOCKS5 proxy infrastructure. These extensions, downloaded nearly 75,000 times and primarily targeting Russian-speaking users, impersonated legitimate VPN brands, allowing an adversary-in-the-middle to observe browsing activity and data.
Researchers demonstrate 'Plug And Pwn' attack for Windows SYSTEM access via USB auto-install
Security researchers Alejandro Hernando and Borja Martinez have unveiled "Plug And Pwn" attacks that exploit the Windows Plug and Play (PnP) feature to achieve SYSTEM-level code execution. This method abuses the automatic installation of vendor software for emulated USB devices, allowing an unprivileged user to gain high-level access on Windows 11 machines. The attack can be triggered physically or remotely under specific conditions.
BdThemes WordPress Plugins Removed After Supply Chain Attack Creates Rogue Admins
A supply chain attack on BdThemes, a WordPress plugin vendor, led to the compromise of their infrastructure and the modification of a remote JSON feed. This allowed attackers to create rogue administrator accounts on WordPress sites using affected plugins, prompting WordPress.org to remove all BdThemes products, impacting over 350,000 active installations.
New CSS Attacks Bypass Webmail Defenses, Enabling Password and Token Theft
New research by PortSwigger's Gareth Heyes, presented at Black Hat USA 2026, demonstrates CSS-based attacks that allow email content to escape its message boundary and interact with webmail interfaces. These techniques can capture passwords, exfiltrate tokens, and hijack UI actions across major webmail providers like Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail.
Zbtlink Routers Found with Factory-Shipped Backdoor, Codename ENDLESSDOORS
Cybersecurity researchers at VulnCheck discovered a factory-shipped backdoor, codenamed ENDLESSDOORS, in at least 20 Zbtlink router models. This implant, present in all 21 available firmware images over two years, establishes an unauthenticated root shell and beacons to Chinese command-and-control infrastructure, posing a significant security risk by allowing remote control and bypassing typical network defenses.
77 Malicious "Evil Twin" Extensions Removed from Open VSX Marketplace
Manifold Security discovered 77 malicious "evil twin" extensions on the Open VSX marketplace between July 26 and August 1, 2026. These extensions mimicked legitimate developer tools and exfiltrated system and development environment information, leading to their removal from Open VSX on August 3, 2026.
Greatness PhaaS Adds Device Code Phishing, Targets Microsoft 365 Accounts
The Greatness phishing-as-a-service (PhaaS) toolkit now supports device code phishing, exploiting the OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and compromise user accounts. This update allows attackers to steal MFA-approved authentication tokens and maintain access to compromised accounts, posing a greater threat to online security. The platform is sold for $289 per month and targets platforms including Microsoft 365, iCloud, Yahoo, and Google Workspace.